Rivetway ยท Security & Trust
Security and trust for Rivetway fleet management software
Learn how Rivetway approaches authenticated access, role-based permissions, company separation, auditability, engineering checks and beta safeguards. Rivetway is designed so access controls, company boundaries and operational accountability are part of the product rather than an afterthought. This public overview explains the approach without publishing sensitive implementation details that could unnecessarily increase the attack surface.
Authenticated and role-aware access
Private operational areas require an authenticated account. The information and actions available to a user are intended to follow their role and company context, so somebody can perform the work they are responsible for without automatically receiving unrestricted access to every part of the platform. Public product pages and demo areas remain separate from live customer workspaces.
Company separation in a multi-tenant platform
Rivetway is built as a multi-tenant service, with operational records associated with the appropriate organisation workspace. The platform is designed to keep one company's working data separate from another company's records. Access checks and company context are therefore treated as part of the application model rather than relying on users to avoid the wrong records manually.
Auditability and evidence
Where workflows support audit history, important actions can be retained with the operational record so authorised teams can understand what happened and when. Rivetway's wider product approach is evidence-led: unknown information should remain unknown until it is recorded, rather than being presented as confirmed status without supporting evidence.
Engineering checks and beta safeguards
Quality, security and regression checks are used as the product changes, alongside deployment monitoring. Beta access remains controlled while those safeguards continue to be refined. The public demo uses example information and is deliberately separated from live customer records and privileged operations.
A clear security position
No software service can promise zero risk. Rivetway therefore focuses on layered access controls, separation, traceability and ongoing review, while deliberately keeping credentials, private endpoints, database structure, recovery secrets and other sensitive infrastructure details out of public documentation. For information about personal data and data-protection rights, read the Rivetway privacy notice.